CVE-2026-66302
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 0.54%
- CWE
- CWE-73
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- Microsoft Skype for Business Server 2015 CU13
- Microsoft Skype for Business Server 2019 CU8
- Microsoft Skype for Business Server Subscription Edition CU1
Weakness type
Related vulnerabilities
- CVE-2026-86751 — Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown
- CVE-2026-86741 — Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA
- CVE-2026-79692 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87815 — SiYuan before v3.8.2 Path Traversal via removeRiffDeck
- CVE-2026-53581 — ntp: write path traversal
- CVE-2026-86995 — n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
- CVE-2026-78620 — Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling
- CVE-2026-62804 — Microsoft Word Remote Code Execution Vulnerability